CVE Database /
CVE-2026-40721
CVE · High
CVE-2026-40721 — Element Pack Pro [bdthemes-element-pack] < 9.1.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-40721
|
Element Pack Pro [bdthemes-element-pack] < 9.1.0 |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') |
High
7.5
|
< 9.1.0
|
9.1.0 |
2026-06-17 |
—
|
CVE-2026-40721
A vulnerability has been discovered in Element Pack Pro plugins prior to version 9.0.7, which allows an attacker with contributor-level access to inject arbitrary local files into the application through a malformed input field. This flaw can be exploited by manipulating user input to bypass security checks and gain unauthorized access to sensitive data or system resources.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings